header-logo
Suggest Exploit
vendor:
NovaBoard
by:
Brain[Pillow]
7.5
CVSS
HIGH
Blind SQL-Injection, Standart SQL-Injection, SQL-Injection in Auth, Local Include and Shell Upload
89, 89, 89, 94, 94
CWE
Product Name: NovaBoard
Affected Version From: 1.0.0
Affected Version To: 1.0.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

Brain[Pillow] Blind SQL-Injection, Standart SQL-Injection, SQL-Injection in Auth, Local Include and Shell Upload Vulnerabilities

Brain[Pillow] is vulnerable to Blind SQL-Injection, Standart SQL-Injection, SQL-Injection in Auth, Local Include and Shell Upload. Blind SQL-Injection can be exploited by sending a crafted request to the vulnerable application with magic quotes set to off. Standart SQL-Injection can be exploited by sending a crafted request to the vulnerable application with magic quotes set to off. SQL-Injection in Auth can be exploited by setting the cookie nova_name to admin'# and nova_password to 1c20a3e48e3b6607fedded430a20f606 with magic quotes set to off. Local Include can be exploited by setting the cookie nova_lang to ../index.php%00 with no cookie nova_name in the browser and magic quotes set to off. Shell Upload can be exploited by sending a crafted request to the vulnerable application with magic quotes set to off and uploading a shell with .php extension.

Mitigation:

Ensure that magic quotes are enabled and all user input is properly sanitized and validated.
Source

Exploit-DB raw data: